Verified findings
15
across 15 projects, each named in an advisory published by someone else
Each row is an advisory published by someone else whose credit names this research as the reporter. The link on every identifier goes to the source that establishes the credit, not to a summary of it.
These are external credits. The dossiers this platform researches and writes itself are research records, and the advisories derived from them are indexed separately.
Every figure below is counted from the 15 verified credits on this page - not sampled, not projected. Selecting a value emphasises the findings that carry it; nothing is ever hidden.
Verified findings
15
across 15 projects, each named in an advisory published by someone else
High severity
8
of 15, by the advisory's own band
high 8 · medium 6 · low 1
Fixes shipped
14
of 15 name the release carrying the fix
1 has a full record here
Findings by weakness class. Only 2 classes appear more than once.
10 further classes with 10 findings between them, each appearing once.
Symlink escape in Builder::append_dir_all allows a privileged process to read a file outside the intended root into the archive.
Operation on a resource after expiry, with an authorization check that could be bypassed.
Prototype pollution reachable through request handling, leading to information exposure.
Race condition in request handling.
Uncontrolled resource consumption when decoding a crafted token.
Incorrect calculation of buffer size leading to an out-of-bounds write.
Symlink following on an output path, exposing information outside the intended location.
Command injection through unsanitised input reaching process execution.
Uncontrolled resource consumption from an unbounded allocation.
Missing authorization on a request path.
XML injection through incorrectly neutralised markup.
Uncontrolled resource consumption reachable from a crafted request.
Path traversal during encrypted 7z password verification allowed a file outside the extraction directory to be deleted.
Stored cross-site scripting from input that was not correctly sanitised.
Integer overflow in BTF length checking.